6 ms·
In addition to CAPTCHAs, why not just have a button that runs some JavaScript that completes a proof-of-work similar to what mining bitcoins does? You could mak
by beeboop 11y ago
In addition to CAPTCHAs, why not just have a button that runs some JavaScript that completes a proof-of-work similar to what mining bitcoins does? You could make it only take 5 seconds on a modern laptop CPU, about as long as it'd take to enter the CAPTCHA anyway, but it'd potentially be a very large road block for spammers/DDOSers.
For those on phones, you can still opt for CAPTCHA if you don't want to kill your battery.
- JoeAltmaier 11y agoLove it! I hope almost all authentication will become automated. My personal client machine is much better at proving who it (I) am that a human.
- mikeash 11y agoI did this with the comments box on my blog. I don't think it's technically effective, because doing proof of work in JavaScript is orders of magnitude slower than doing it natively (especially with GPU acceleration). It works well enough for me, because I'm not a big enough target, but it wouldn't be a major obstacle for someone who really wanted to cause havoc. It would be interesting to see how fast you could make the JavaScript code. I'm sure my version is just terribly unoptimized. The requirement to support the least common denominator will present a major problem, though.
- tne 11y agoI would look at asm.js, do some tests with major browsers and beef it up. It would make it painful under user agents that don't JIT (or compile AOT) by leveraging asm.js conventions (many do though). If the wasm effort works out (it's looking like it will), it would hopefully alleviate the issue you present entirely and make this solution viable in a very sane way.
- pfg 11y agoSpending 5 CPU seconds to submit one comment might be significantly cheaper for a spammer than paying someone to solve the captcha for them. Additionally, specifically with Tor users, you can expect a large chunk of the user base to have JavaScript disabled completely. You can do many things with JavaScript that could be used to build a browser fingerprint, so someone who's already using software to browse the web anonymously is very likely to disable that.
- beeboop 11y agoBut it isn't cheaper than just mining bitcoins with that same CPU load. This wouldn't prevent spamming, it would just make it unprofitable compared to the alternatives (mining bitcoins). The JavaScript issue can be gotten around with a browser plugin that does it as well, which would be easy to bundle on the existing Tor browser. JavaScript would still be fine for all the VPN users who get stuck with these things, and the regular users who get them occasionally for whatever reason.
- pfg 11y agoYou're not going to make any significant profit mining bitcoin on a desktop CPU, or any "normal" CPU for that matter. If we assume 5 seconds of CPU time per comment, that's ~17k per day or ~500k per month. The first captcha solving service I found sells 100k solved captchas for $139, so that's about $700 for 500k. As a spammer, I could probably post 5 to 10 times more comments for the same amount of money using your system. This is obviously a very rough estimate, but it should get my point across.
- dgfofd09fv 11y agoBecause that wouldn't stop them. Let's rather say instead everyone gets a fixed delay in seconds. Then the spammers will just wait out that delay and then spam. Even if the delay is on every single page visit, that doesn't harm a botnet, because they can still do delay/machine_count visits per second.
- beeboop 11y agoIt doesn't stop them, but it raises the costs of it significantly. Instead of hundreds of requests a second, they're down to one request every 5 seconds, and they're having to run the computer at a full CPU load 100% of the time. It would be more profitable for them to just mine bitcoins at this point, meaning they wouldn't waste that CPU load on spam submissions.
- dgfofd09fv 11y agoYou're mixing the two cases. If every page is limited then yes they have to work hard, but still get delay/machines visits per second. But a human will have to wait the full delay every time a page is visited. This is unacceptable for modern browsing. If the delay is only once per, let's say a domain, then you don't do anything against the spammers, they only have to wait a full delay once.
- deleted 11y ago[deleted]
- beeboop 11y agoMaybe Cloudflare could have a browser plugin that preemptively creates "tokens", or essentially just mines Cloudcoins that you then spend to bypass CAPTCHAs. That way you could make it much more expensive than 5 seconds of CPU and there'd be zero delay (or perhaps not even the Cloudflare splash page). The use case for needing to constantly bypass CAPTCHAs is rare enough it seems reasonable to ask those people to use a browser plugin.
- deleted 11y ago
- iokanuon 11y agoIt's better to not use javascript with TOR, the browser even suggests you to disable it.
- chejazi 11y agoI experimented with this [1] using GPU acceleration. Last I was working on it, phones required you to manually enable WebGL in the browser and even then I couldn't get it to work on mobile. I shelved it, though I probably could have gotten it working. [1] https://s3-us-west-2.amazonaws.com/excredo/hashrate.html https://s3-us-west-2.amazonaws.com/excredo/hashrate.html